![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Apr 2009
Posts: 5
OS: xp home
|
Sinowal-FV recurring infection
Hi,
In advance I would like to say many thanks to any responses I get from this forum, I am new here and have heard very good things about you guys. I am running XP Home and have Avast! antivirus installed and with the definitions updated. In the last few days I have had several infections stemming from -what I believe to be - having used my USB in another university colleague's laptop. I was initially infected with 'Cool USEP Scandal.vbs', 'sowar.vbs'; and 'Autorun.inf' - avast detected these and following this I placed them in the chest and deleted the content of the chest. Following this I have been infected with 'Sinowal-FV [Spy]' located in C:\Documents and Settings\All Users\Start Menu\Programs\Startup\uninstall.exe - Avast detects this on start up of windows and I chest and delete the contents of chest as per usual. However with 'Sinowal' on each startup the file re-appears. Any help would be greatly appreciated. Dominic DDS Log: DDS (Ver_09-03-16.01) - NTFSx86 Run by Dominic G at 11:55:02.20 on 28/04/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.511.215 [GMT 1:00] AV: avast! antivirus 4.8.1335 [VPS 090427-0] *On-access scanning enabled* (Updated) AV: F-Secure Anti-Virus Client Security 6.00 *On-access scanning enabled* (Outdated) ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Icecast2 Win32\icecastService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Kontiki\KService.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Toshiba\Tvs\TvsTray.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe C:\WINDOWS\system32\TPSMain.exe C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe C:\WINDOWS\system32\TPSBattM.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Razer\Copperhead\razerhid.exe C:\Program Files\Razer\Copperhead\razerofa.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\notepad.exe C:\Documents and Settings\Dominic G\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.uk/ uInternet Connection Wizard,ShellNext = iexplore BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Athens Toolbar: {2e560504-b9c8-48aa-982a-08b79c3fd40e} - c:\program files\eduserv technologies limited\athens toolbar\AthensToolbar.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 uRun: [Sonic RecordNow!] mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe mRun: [TPSMain] TPSMain.exe mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe mRun: [TFncKy] TFncKy.exe mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray mRun: [CFSServ.exe] CFSServ.exe -NoClient mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [razer] c:\program files\razer\copperhead\razerhid.exe mRun: [tsnp2std] c:\windows\tsnp2std.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [4oD] "c:\program files\kontiki\KHost.exe" -all mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe" mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mExplorerRun: [wininet.dll] regperf.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\device~1.lnk - c:\program files\olympus\devicedetector\DevDtct2.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v2\WG111v2.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nokian~1.lnk - c:\program files\nokia\nnpcs\RunLauncher.exe StartupFolder: c:\documents and settings\all users\start menu\programs\startup\uninstall.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Trusted Zone: nationwide.co.uk DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1205747902062 DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1164545496780 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab DPF: {BD393C14-72AD-4790-A095-76522973D6B8} - hxxp://messenger.zone.msn.com/binary/Bankshot.cab57213.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\domini~1\applic~1\mozilla\firefox\profiles\cpde31gj.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?refresh=1 FF - prefs.js: network.proxy.ftp - 127.0.0.1 FF - prefs.js: network.proxy.ftp_port - 8080 FF - prefs.js: network.proxy.gopher - 5.6.7.8 FF - prefs.js: network.proxy.gopher_port - 8080 FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 8080 FF - prefs.js: network.proxy.socks - 127.0.0.1 FF - prefs.js: network.proxy.socks_port - 1080 FF - prefs.js: network.proxy.ssl_port - 8080 FF - prefs.js: network.proxy.type - 4 FF - plugin: c:\program files\mozilla firefox\plugins\npBBCPlugin.dll ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-3-31 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-3-31 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2006-10-8 138680] R2 Icecast-trunk;Icecast-trunk Streaming Media Server;c:\program files\icecast2 win32\icecastService.exe [2008-10-14 417792] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2006-10-8 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2006-10-8 352920] S2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [2007-9-8 46336] S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};\??\c:\windows\temp\49.tmp --> c:\windows\temp\49.tmp [?] S3 iscFlash;iscFlash;\??\c:\docume~1\domini~1\locals~1\temp\isc45tmp\iscflash.sys --> c:\docume~1\domini~1\locals~1\temp\isc45tmp\iscflash.sys [?] S3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\drivers\KORGUMDS.SYS [2008-10-29 21720] S3 PAC7311;VGA USB Camera;c:\windows\system32\drivers\pa707ucm.sys --> c:\windows\system32\drivers\PA707UCM.SYS [?] S3 Razerlow;Razer Copperhead Driver;c:\windows\system32\drivers\Razerlow.sys [2007-4-17 19020] =============== Created Last 30 ================ 2009-04-03 15:29 <DIR> --d----- c:\program files\GPLGS 2009-04-03 15:27 87,552 a------- c:\windows\system32\cpwmon2k.dll 2009-04-03 15:26 <DIR> --d----- c:\program files\Acro Software ==================== Find3M ==================== 2009-03-09 05:19 410,984 a------- c:\windows\system32\deploytk.dll 2009-03-06 15:22 284,160 a------- c:\windows\system32\pdh.dll 2009-03-03 01:18 826,368 a------- c:\windows\system32\wininet.dll 2009-02-20 19:09 78,336 a------- c:\windows\system32\ieencode.dll 2009-02-09 13:10 729,088 a------- c:\windows\system32\lsasrv.dll 2009-02-09 13:10 714,752 a------- c:\windows\system32\ntdll.dll 2009-02-09 13:10 617,472 a------- c:\windows\system32\advapi32.dll 2009-02-09 13:10 401,408 a------- c:\windows\system32\rpcss.dll 2009-02-09 12:13 1,846,784 a------- c:\windows\system32\win32k.sys 2009-02-07 19:02 2,066,048 a------- c:\windows\system32\ntkrnlpa.exe 2009-02-06 12:11 110,592 a------- c:\windows\system32\services.exe 2009-02-06 12:08 2,189,056 a------- c:\windows\system32\ntoskrnl.exe 2009-02-06 11:39 35,328 a------- c:\windows\system32\sc.exe 2009-02-03 20:59 56,832 a------- c:\windows\system32\secur32.dll 2008-04-07 09:41 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat 2008-10-12 13:18 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101220081013\index.dat ============= FINISH: 11:56:16.35 =============== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,581
OS: Vista
|
Re: Sinowal-FV recurring infection
Hi,
Do you still have F-Secure installed there or have you uninstalled it already? *download this file, save it to your desktop. http://www2.gmer.net/mbr/mbr.exe double click it then a log called mbr.log will be created on your desktop. Post the contents please. *Please visit this webpage for download links, and instructions for running combofix: http://www.bleepingcomputer.com/comb...o-use-combofix * Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Please include the C:\ComboFix.txt in your next reply for further review.
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Apr 2009
Posts: 5
OS: xp home
|
Re: Sinowal-FV recurring infection
Hi,
Many thanks for the response. As far as I was aware F-Secure was un-installed - ComboFix shows the contrary - I had been given it as a preventative measure by the University when I started 3 years ago - I realised about a year ago I wanted to use avast instead so removed F-Secure (as far as I was aware). Currently it does not appear in the system tray; in add/remove programmes; nor can I find it anywhere else..... Do you have any recommendations as to how I can remove it completely? So, I therefore ran ComboFix despite it saying that F-Secure was running . Attached are the two requested logs: Combofix.txt and mbr.txt The computer appears to be still infected... Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.4 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> 0x82900032 NDIS: Marvell Yukon 88E8036 PCI-E Fast Ethernet Controller -> SendCompleteHandler -> 0x82936e00 Warning: possible MBR rootkit infection ! user & kernel MBR OK MBR rootkit code detected ! malicious code @ sector 0x94a8527 size 0x1e4 ! copy of MBR has been found in sector 62 ! MBR rootkit infection detected ! Use: "mbr.exe -f" to fix. ComboFix 09-04-29.03 - Dominic G 30/04/2009 10:22.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.511.161 [GMT 1:00] Running from: c:\documents and settings\Dominic G\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1335 [VPS 090429-0] *On-access scanning disabled* (Updated) AV: F-Secure Anti-Virus Client Security 6.00 *On-access scanning enabled* (Outdated) * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-30 ))))))))))))))))))))))))))))))) . 2009-04-29 19:14 . 2009-04-29 19:14 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-04-29 19:10 . 2009-04-29 19:11 -------- d-----w c:\program files\SUPERAntiSpyware 2009-04-29 19:10 . 2009-04-29 19:10 -------- d-----w c:\documents and settings\Dominic G\Application Data\SUPERAntiSpyware.com 2009-04-29 19:10 . 2009-04-29 19:10 -------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-04-29 17:16 . 2009-04-30 08:36 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-04-29 17:16 . 2009-04-29 17:24 -------- d-----w c:\program files\Spybot - Search & Destroy 2009-04-28 14:41 . 2009-04-28 14:41 -------- d-----w c:\documents and settings\Dominic G\Application Data\Malwarebytes 2009-04-28 14:41 . 2009-04-06 14:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-04-28 14:40 . 2009-04-06 14:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-28 14:40 . 2009-04-28 14:40 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes 2009-04-28 14:40 . 2009-04-28 14:41 -------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-04-19 22:09 . 2009-04-19 22:09 -------- d-----w c:\program files\Microsoft Silverlight 2009-04-15 03:41 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll 2009-04-15 03:41 . 2009-02-06 10:39 35328 -c----w c:\windows\system32\dllcache\sc.exe 2009-04-15 03:41 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll 2009-04-15 03:41 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe 2009-04-15 03:41 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll 2009-04-15 03:41 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe 2009-04-15 03:41 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 03:41 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll 2009-04-15 03:41 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll 2009-04-15 03:41 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll 2009-04-15 03:41 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll 2009-04-15 03:41 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe 2009-04-03 14:30 . 2009-04-22 16:36 -------- d-----w c:\documents and settings\Dominic G\Local Settings\Application Data\CutePDF Writer 2009-04-03 14:29 . 2009-04-03 14:29 -------- d-----w c:\program files\GPLGS 2009-04-03 14:27 . 2007-07-12 21:33 87552 ----a-w c:\windows\system32\cpwmon2k.dll 2009-04-03 14:26 . 2009-04-03 14:26 -------- d-----w c:\program files\Acro Software . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-28 10:42 . 2008-02-01 09:09 -------- d-----w c:\program files\Delta Force Black Hawk Down 2009-04-28 10:42 . 2005-01-22 10:25 -------- d--h--w c:\program files\InstallShield Installation Information 2009-04-28 10:41 . 2006-03-31 00:40 -------- d-----w c:\program files\Azureus 2009-04-07 10:27 . 2005-01-22 09:32 -------- d-----w c:\program files\Java 2009-03-25 16:49 . 2009-03-25 16:40 -------- d-----w c:\program files\KORG 2009-03-09 04:19 . 2008-12-07 16:29 410984 ----a-w c:\windows\system32\deploytk.dll 2009-03-06 14:22 . 2005-01-22 08:07 284160 ----a-w c:\windows\system32\pdh.dll 2009-03-03 00:18 . 2005-01-22 08:07 826368 ----a-w c:\windows\system32\wininet.dll 2009-02-20 18:09 . 2005-01-22 08:07 78336 ----a-w c:\windows\system32\ieencode.dll 2009-02-09 12:10 . 2005-01-22 08:07 729088 ----a-w c:\windows\system32\lsasrv.dll 2009-02-09 12:10 . 2005-01-22 08:07 401408 ----a-w c:\windows\system32\rpcss.dll 2009-02-09 12:10 . 2005-01-22 08:07 714752 ----a-w c:\windows\system32\ntdll.dll 2009-02-09 12:10 . 2005-01-22 08:06 617472 ----a-w c:\windows\system32\advapi32.dll 2009-02-09 11:13 . 2005-01-22 08:07 1846784 ----a-w c:\windows\system32\win32k.sys 2009-02-07 18:02 . 2004-08-03 22:59 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe 2009-02-06 11:11 . 2005-01-22 08:07 110592 ----a-w c:\windows\system32\services.exe 2009-02-06 11:08 . 2005-01-22 08:07 2189056 ----a-w c:\windows\system32\ntoskrnl.exe 2009-02-06 10:39 . 2005-01-22 08:07 35328 ----a-w c:\windows\system32\sc.exe 2009-02-03 19:59 . 2005-01-22 08:07 56832 ----a-w c:\windows\system32\secur32.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218] "Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2004-11-12 73728] "THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2005-01-14 352256] "SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-12-21 118784] "PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 1077327] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-03 122939] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 339968] "SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-23 180269] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000] "razer"="c:\program files\Razer\Copperhead\razerhid.exe" [2005-10-08 155648] "tsnp2std"="c:\windows\tsnp2std.exe" [2007-01-05 258048] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352] "4oD"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136] "NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888] "AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2004-10-28 88363] "TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-01-21 266240] "TFncKy"="TFncKy.exe" [BU] "CFSServ.exe"="CFSServ.exe" [BU] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-7-2 113664] Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696] Device Detector 3.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2008-7-1 114688] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 11:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32 "midi5"= KORGUMDD.DRV [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Kontiki\\KService.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Icecast2 Win32\\Icecast2win.exe"= "c:\\Program Files\\Valve\\Steam\\SteamApps\\missedthebus\\counter-strike source\\hl2.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "14400:TCP"= 14400:TCP:AzureusPORTIN "14400:UDP"= 14400:UDP:AzureusPORTOUT R2 Icecast-trunk;Icecast-trunk Streaming Media Server;c:\program files\Icecast2 Win32\icecastService.exe [2008-05-24 417792] R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\Drivers\ousbehci.sys [2007-03-26 46336] R3 iscFlash;iscFlash; [x] R3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\Drivers\KORGUMDS.SYS [2008-10-29 21720] R3 PAC7311;VGA USB Camera; [x] R3 Razerlow;Razer Copperhead Driver;c:\windows\system32\Drivers\Razerlow.sys [2005-08-12 19020] S1 aswSP;avast! Self Protection; [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944] S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23c27880-bca2-11dd-b0a3-0012f0bfc8e6}] \Shell\AutoRun\command - e:\peninkviewer\Viewer_for_Windows\PenInkViewer.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8cd0ccb0-e85d-11dc-af82-0012f0bfc8e6}] \Shell\Auto\command - msnmsgr_plus.exe \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL msnmsgr_plus.exe . Contents of the 'Scheduled Tasks' folder 2009-04-25 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:57] . - - - - ORPHANS REMOVED - - - - HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe HKCU-Run-Sonic RecordNow! - (no file) . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk/ uInternet Connection Wizard,ShellNext = iexplore IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 Trusted Zone: nationwide.co.uk FF - ProfilePath - c:\documents and settings\Dominic G\Application Data\Mozilla\Firefox\Profiles\cpde31gj.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?refresh=1 FF - prefs.js: network.proxy.ftp - 127.0.0.1 FF - prefs.js: network.proxy.ftp_port - 8080 FF - prefs.js: network.proxy.gopher - 5.6.7.8 FF - prefs.js: network.proxy.gopher_port - 8080 FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 8080 FF - prefs.js: network.proxy.socks - 127.0.0.1 FF - prefs.js: network.proxy.socks_port - 1080 FF - prefs.js: network.proxy.ssl_port - 8080 FF - prefs.js: network.proxy.type - 4 FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npBBCPlugin.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-30 10:25 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(780) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(3532) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\windows\system32\TPwrCfg.DLL c:\windows\system32\TPwrReg.dll c:\windows\system32\TPSTrace.DLL . Completion time: 2009-04-30 10:29 ComboFix-quarantined-files.txt 2009-04-30 09:28 Pre-Run: 7,699,673,088 bytes free Post-Run: 9,602,174,976 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect 209 --- E O F --- 2009-04-16 08:16 Kind Regards Dominic Last edited by Angelfire777; 04-30-2009 at 12:47 PM. |
|
|
|
|
#4 (permalink) | |
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,581
OS: Vista
|
Re: Sinowal-FV recurring infection
Hi,
Do you know what PenInkViewer is? Quote:
![]() 1. Click on the Start menu. 2. Select Run... 3. Type wbemtest and click OK 4. Connect to root/SecurityCenter 5. Click on Query 6. Type in SELECT * FROM AntiVirusProduct and click on Apply If there is more than one result, it means there is more than one Antivirus program installed. Double click on each result to view the properties for that Antivirus product. Identify the product(s) installed and DELETE any records for an Antivirus software that is no longer installed. Uninstall these older versions of java in control panel > add or remove programs. They use up unnecessary space and are vulnerabilities. J2SE Runtime Environment 5.0 J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 11 J2SE Runtime Environment 5.0 Update 6 J2SE Runtime Environment 5.0 Update 9 Java(TM) 6 Update 2 Java(TM) 6 Update 3 Java(TM) 6 Update 5 Java(TM) 6 Update 7 Java(TM) SE Runtime Environment 6 Update 1 *click start > run > copy and paste: cmd /c "%userprofile%\desktop\mbr.exe" -f > check.txt&check.txt a log will pop out, please post the contents on your next reply. *Open notepad. Copy and paste the text inside the code box below to notepad Code:
Folder::
c:\program files\Azureus
Driver::
iscFlash
PAC7311
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14400:TCP"=-
"14400:UDP"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8cd0ccb0-e85d-11dc-af82-0012f0bfc8e6}]
DDS::
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
![]() Refering to the picture above, drag CFScript.txt into ComboFix.exe When finished, it shall produce a log for you. Post that log in your next reply. *Next, it's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course: Using Internet Explorer or Firefox, visit http://www.kaspersky.com/kos/eng/par...avwebscan.html 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
On your next reply, please include a
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. |
|
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Apr 2009
Posts: 5
OS: xp home
|
Re: Sinowal-FV recurring infection
Hi,
I have followed through your instructions as said: F-Secure was removed correctly; all old versions of Java were removed. I ran the mbr code the results of which are attached. I also ran the CFScript, this was fine, however I did not realise that ComboFix would reboot the system and so I did not choose to persist changes when turning off the virus scanner (i.e. therefore it was open again on reboot). On reboot, avast! found the virus again - so I quarantined this and ended avast!, then continued the Combo Fix and created the log. The kaspersky scan proved to be free from infection however as avast! picked up the file on start up it obviously is not free of infection yet... ![]() I have attached both files asked for and also the avast log to show that avast is still picking up the virus. Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.4 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> 0x82717032 NDIS: Marvell Yukon 88E8036 PCI-E Fast Ethernet Controller -> SendCompleteHandler -> 0x8274de00 Warning: possible MBR rootkit infection ! user & kernel MBR OK MBR rootkit code detected ! malicious code @ sector 0x94a8527 size 0x1e4 ! copy of MBR has been found in sector 62 ! MBR rootkit infection detected ! Use: "mbr.exe -f" to fix. original MBR restored successfully ! ----------------------------- ComboFix 09-04-29.03 - Dominic G 30/04/2009 22:36.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.511.163 [GMT 1:00] Running from: c:\documents and settings\Dominic G\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Dominic G\Desktop\CFScript.txt AV: avast! antivirus 4.8.1335 [VPS 090430-0] *On-access scanning disabled* (Updated) * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Azureus c:\program files\Azureus\javaw.exe.manifest c:\program files\Azureus\msvcr71.dll c:\program files\Azureus\plugins\azplugins\azplugins_1.9.1.jar c:\program files\Azureus\plugins\azplugins\azplugins_2.0.jar c:\program files\Azureus\plugins\azplugins\azplugins_2.1.1.jar c:\program files\Azureus\plugins\azplugins\azplugins_2.1.4.jar c:\program files\Azureus\plugins\azrating\azrating_1.3.1.jar c:\program files\Azureus\plugins\azrating\azrating_1.3.jar c:\program files\Azureus\plugins\azupdater\azupdater_1.8.5.zip c:\program files\Azureus\plugins\azupdater\azupdater_1.8.8.zip c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.3.jar c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.5.jar c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.8.jar c:\program files\Azureus\plugins\azupdater\plugin.properties c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.5 c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.8 c:\program files\Azureus\plugins\azupdater\Updater.jar c:\program files\Azureus\plugins\azupdater\Updater.jar.bak c:\program files\Azureus\plugins\azupnpav\azupnpav_0.1.3.jar c:\program files\Azureus\plugins\azupnpav\azupnpav_0.1.3.zip c:\program files\Azureus\plugins\azupnpav\azupnpav_0.1.7.jar c:\program files\Azureus\plugins\azupnpav\azupnpav_0.1.7.zip c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.2.jar c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.2.zip c:\program files\Azureus\plugins\azupnpav\plugin.properties_0.1.3 c:\program files\Azureus\plugins\azupnpav\plugin.properties_0.1.7 c:\program files\Azureus\plugins\azupnpav\plugin.properties_0.2.2 c:\program files\Azureus\swt-awt-win32-3139.dll c:\program files\Azureus\swt-awt-win32-3318.dll c:\program files\Azureus\swt-gdip-win32-3139.dll c:\program files\Azureus\swt-gdip-win32-3318.dll c:\program files\Azureus\swt-wgl-win32-3318.dll c:\program files\Azureus\swt-win32-3139.dll c:\program files\Azureus\swt-win32-3318.dll c:\program files\Azureus\uninstall.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ISCFLASH -------\Service_iscFlash -------\Service_PAC7311 ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-30 ))))))))))))))))))))))))))))))) . 2009-04-29 19:14 . 2009-04-29 19:14 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-04-29 19:10 . 2009-04-29 19:11 -------- d-----w c:\program files\SUPERAntiSpyware 2009-04-29 19:10 . 2009-04-29 19:10 -------- d-----w c:\documents and settings\Dominic G\Application Data\SUPERAntiSpyware.com 2009-04-29 19:10 . 2009-04-29 19:10 -------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-04-29 17:16 . 2009-04-30 08:36 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-04-29 17:16 . 2009-04-29 17:24 -------- d-----w c:\program files\Spybot - Search & Destroy 2009-04-28 14:41 . 2009-04-28 14:41 -------- d-----w c:\documents and settings\Dominic G\Application Data\Malwarebytes 2009-04-28 14:41 . 2009-04-06 14:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-04-28 14:40 . 2009-04-06 14:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-28 14:40 . 2009-04-28 14:40 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes 2009-04-28 14:40 . 2009-04-28 14:41 -------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-04-19 22:09 . 2009-04-19 22:09 -------- d-----w c:\program files\Microsoft Silverlight 2009-04-15 03:41 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll 2009-04-15 03:41 . 2009-02-06 10:39 35328 -c----w c:\windows\system32\dllcache\sc.exe 2009-04-15 03:41 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll 2009-04-15 03:41 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe 2009-04-15 03:41 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll 2009-04-15 03:41 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe 2009-04-15 03:41 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 03:41 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll 2009-04-15 03:41 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll 2009-04-15 03:41 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll 2009-04-15 03:41 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll 2009-04-15 03:41 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe 2009-04-03 14:30 . 2009-04-22 16:36 -------- d-----w c:\documents and settings\Dominic G\Local Settings\Application Data\CutePDF Writer 2009-04-03 14:29 . 2009-04-03 14:29 -------- d-----w c:\program files\GPLGS 2009-04-03 14:27 . 2007-07-12 21:33 87552 ----a-w c:\windows\system32\cpwmon2k.dll 2009-04-03 14:26 . 2009-04-03 14:26 -------- d-----w c:\program files\Acro Software . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-30 21:15 . 2005-01-22 09:32 -------- d-----w c:\program files\Java 2009-04-28 10:42 . 2008-02-01 09:09 -------- d-----w c:\program files\Delta Force Black Hawk Down 2009-04-28 10:42 . 2005-01-22 10:25 -------- d--h--w c:\program files\InstallShield Installation Information 2009-03-25 16:49 . 2009-03-25 16:40 -------- d-----w c:\program files\KORG 2009-03-09 04:19 . 2008-12-07 16:29 410984 ----a-w c:\windows\system32\deploytk.dll 2009-03-06 14:22 . 2005-01-22 08:07 284160 ----a-w c:\windows\system32\pdh.dll 2009-03-03 00:18 . 2005-01-22 08:07 826368 ----a-w c:\windows\system32\wininet.dll 2009-02-20 18:09 . 2005-01-22 08:07 78336 ----a-w c:\windows\system32\ieencode.dll 2009-02-09 12:10 . 2005-01-22 08:07 729088 ----a-w c:\windows\system32\lsasrv.dll 2009-02-09 12:10 . 2005-01-22 08:07 401408 ----a-w c:\windows\system32\rpcss.dll 2009-02-09 12:10 . 2005-01-22 08:07 714752 ----a-w c:\windows\system32\ntdll.dll 2009-02-09 12:10 . 2005-01-22 08:06 617472 ----a-w c:\windows\system32\advapi32.dll 2009-02-09 11:13 . 2005-01-22 08:07 1846784 ----a-w c:\windows\system32\win32k.sys 2009-02-07 18:02 . 2004-08-03 22:59 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe 2009-02-06 11:11 . 2005-01-22 08:07 110592 ----a-w c:\windows\system32\services.exe 2009-02-06 11:08 . 2005-01-22 08:07 2189056 ----a-w c:\windows\system32\ntoskrnl.exe 2009-02-06 10:39 . 2005-01-22 08:07 35328 ----a-w c:\windows\system32\sc.exe 2009-02-03 19:59 . 2005-01-22 08:07 56832 ----a-w c:\windows\system32\secur32.dll . ((((((((((((((((((((((((((((( SnapShot@2009-04-30_09.25.52 ))))))))))))))))))))))))))))))))))))))))) . + 2009-04-30 21:22 . 2009-04-30 21:22 16384 c:\windows\Temp\Perflib_Perfdata_bd4.dat + 2009-04-30 21:21 . 2009-04-30 21:21 16384 c:\windows\Temp\Perflib_Perfdata_704.dat + 2009-04-30 21:42 . 2009-04-30 21:42 16384 c:\windows\Temp\Perflib_Perfdata_6ec.dat + 2009-04-30 21:42 . 2009-04-30 21:42 16384 c:\windows\Temp\Perflib_Perfdata_598.dat + 2009-04-30 21:42 . 2009-04-30 21:42 16384 c:\windows\Temp\Perflib_Perfdata_550.dat + 2009-04-30 21:42 . 2009-04-30 21:42 16384 c:\windows\Temp\Perflib_Perfdata_4a0.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218] "Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2004-11-12 73728] "THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2005-01-14 352256] "SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-12-21 118784] "PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 1077327] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-03 122939] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 339968] "SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-23 180269] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000] "razer"="c:\program files\Razer\Copperhead\razerhid.exe" [2005-10-08 155648] "tsnp2std"="c:\windows\tsnp2std.exe" [2007-01-05 258048] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352] "4oD"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136] "NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888] "AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2004-10-28 88363] "TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-01-21 266240] "TFncKy"="TFncKy.exe" [BU] "CFSServ.exe"="CFSServ.exe" [BU] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-7-2 113664] Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696] Device Detector 3.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2008-7-1 114688] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 11:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32 "midi5"= KORGUMDD.DRV [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Kontiki\\KService.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Icecast2 Win32\\Icecast2win.exe"= "c:\\Program Files\\Valve\\Steam\\SteamApps\\missedthebus\\counter-strike source\\hl2.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\Drivers\ousbehci.sys [2007-03-26 46336] R3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\Drivers\KORGUMDS.SYS [2008-10-29 21720] R3 Razerlow;Razer Copperhead Driver;c:\windows\system32\Drivers\Razerlow.sys [2005-08-12 19020] S1 aswSP;avast! Self Protection; [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944] S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560] S2 Icecast-trunk;Icecast-trunk Streaming Media Server;c:\program files\Icecast2 Win32\icecastService.exe [2008-05-24 417792] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23c27880-bca2-11dd-b0a3-0012f0bfc8e6}] \Shell\AutoRun\command - e:\peninkviewer\Viewer_for_Windows\PenInkViewer.exe . Contents of the 'Scheduled Tasks' folder 2009-04-25 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:57] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk/ uInternet Connection Wizard,ShellNext = iexplore IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 Trusted Zone: nationwide.co.uk FF - ProfilePath - c:\documents and settings\Dominic G\Application Data\Mozilla\Firefox\Profiles\cpde31gj.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?refresh=1 FF - prefs.js: network.proxy.ftp - 127.0.0.1 FF - prefs.js: network.proxy.ftp_port - 8080 FF - prefs.js: network.proxy.gopher - 5.6.7.8 FF - prefs.js: network.proxy.gopher_port - 8080 FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 8080 FF - prefs.js: network.proxy.socks - 127.0.0.1 FF - prefs.js: network.proxy.socks_port - 1080 FF - prefs.js: network.proxy.ssl_port - 8080 FF - prefs.js: network.proxy.type - 4 FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npBBCPlugin.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-30 22:49 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(756) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(3248) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\windows\system32\TPwrCfg.DLL c:\windows\system32\TPwrReg.dll c:\windows\system32\TPSTrace.DLL . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\program files\Alwil Software\Avast4\aswUpdSv.exe c:\program files\Alwil Software\Avast4\ashServ.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Kontiki\KService.exe c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\program files\Analog Devices\SoundMAX\SMAgent.exe c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe c:\windows\system32\ati2evxx.exe c:\windows\system32\TPSBattM.exe c:\program files\Razer\Copperhead\razerofa.exe c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe c:\program files\iPod\bin\iPodService.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2009-04-30 22:55 - machine was rebooted ComboFix-quarantined-files.txt 2009-04-30 21:54 Pre-Run: 9,873,948,672 bytes free Post-Run: 9,756,913,664 bytes free 260 --- E O F --- 2009-04-16 08:16 ------------------------------------ -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Friday, May 1, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Thursday, April 30, 2009 23:33:41 Records in database: 2115319 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 110243 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 02:18:52 No malware has been detected. The scan area is clean. The selected area was scanned. Many Thanks Dominic Last edited by Angelfire777; 05-01-2009 at 12:12 AM. |
|
|
|
|
#6 (permalink) |
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,581
OS: Vista
|
Re: Sinowal-FV recurring infection
Please reboot your computer.
Double click mbr.exe again and post the contents of mbr.log
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. |
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Apr 2009
Posts: 5
OS: xp home
|
Re: Sinowal-FV recurring infection
Hi,
Here is the requested mbr log: Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.4 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> 0x833d94d8 NDIS: Marvell Yukon 88E8036 PCI-E Fast Ethernet Controller -> user & kernel MBR OK Now it appears to be resolved! ![]() ![]() ![]() Thank you so much for your help! Dominic |
|
|
|
|
#8 (permalink) |
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,581
OS: Vista
|
Re: Sinowal-FV recurring infection
Click start > run > copy and paste:
combofix /u That will hide your system files, clear your system restore cache and uninstall combofix. Note: Make sure you update your Antivirus programs and other security products regularly to avoid new threats that could infect your system. Read TonyKlein's How Did I Get Infected In The First Place?. Please check out miekiemoes' "How to Prevent Malware" Happy safe surfing! Note: Please reply to this thread one last time so I could mark it as resolved.
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. |
|
|
| Thread Tools | |
|
|